mirror of
https://github.com/roddhjav/apparmor.d.git
synced 2025-01-18 00:48:10 +01:00
Update spectre-meltdown-checker
This commit is contained in:
parent
7f960ff4f7
commit
44bcd2a394
1 changed files with 15 additions and 1 deletions
|
@ -16,6 +16,10 @@ profile spectre-meltdown-checker @{exec_path} {
|
||||||
# Needed to read system logs
|
# Needed to read system logs
|
||||||
capability syslog,
|
capability syslog,
|
||||||
|
|
||||||
|
# Used by readlink
|
||||||
|
capability sys_ptrace,
|
||||||
|
ptrace (read),
|
||||||
|
|
||||||
@{exec_path} r,
|
@{exec_path} r,
|
||||||
/{usr/,}bin/{,ba,da}sh rix,
|
/{usr/,}bin/{,ba,da}sh rix,
|
||||||
|
|
||||||
|
@ -56,6 +60,7 @@ profile spectre-meltdown-checker @{exec_path} {
|
||||||
/{usr/,}bin/mount rix,
|
/{usr/,}bin/mount rix,
|
||||||
/{usr/,}bin/find rix,
|
/{usr/,}bin/find rix,
|
||||||
/{usr/,}bin/xargs rix,
|
/{usr/,}bin/xargs rix,
|
||||||
|
/{usr/,}bin/readlink rix,
|
||||||
|
|
||||||
/{usr/,}bin/pgrep rCx -> pgrep,
|
/{usr/,}bin/pgrep rCx -> pgrep,
|
||||||
/{usr/,}bin/ccache rCx -> ccache,
|
/{usr/,}bin/ccache rCx -> ccache,
|
||||||
|
@ -92,7 +97,11 @@ profile spectre-meltdown-checker @{exec_path} {
|
||||||
@{PROC}/cmdline r,
|
@{PROC}/cmdline r,
|
||||||
@{PROC}/kallsyms r,
|
@{PROC}/kallsyms r,
|
||||||
@{PROC}/modules r,
|
@{PROC}/modules r,
|
||||||
@{PROC}/@{pid}/status r,
|
|
||||||
|
# find and denoise
|
||||||
|
@{PROC}/@{pid}/{status,exe} r,
|
||||||
|
@{PROC}/@{pid}/fd/ r,
|
||||||
|
@{PROC}/*/ r,
|
||||||
|
|
||||||
/var/lib/dbus/machine-id r,
|
/var/lib/dbus/machine-id r,
|
||||||
/etc/machine-id r,
|
/etc/machine-id r,
|
||||||
|
@ -154,6 +163,11 @@ profile spectre-meltdown-checker @{exec_path} {
|
||||||
profile kmod {
|
profile kmod {
|
||||||
include <abstractions/base>
|
include <abstractions/base>
|
||||||
|
|
||||||
|
capability sys_module,
|
||||||
|
|
||||||
|
owner /sys/module/cpuid/** r,
|
||||||
|
owner /sys/module/msr/** r,
|
||||||
|
|
||||||
/{usr/,}bin/kmod mr,
|
/{usr/,}bin/kmod mr,
|
||||||
|
|
||||||
/etc/modprobe.d/ r,
|
/etc/modprobe.d/ r,
|
||||||
|
|
Loading…
Reference in a new issue